Safety authentication method based on cooperation of Beidou short message and automobile display terminal

By using a security authentication method that combines BeiDou short message service with vehicle display terminals, the problem of granting temporary driving permissions in areas without network coverage is solved. This enables secure identity verification and permission activation in emergency situations, ensuring information transmission security and centralized decision-making.

CN120750550BActive Publication Date: 2025-12-12SICHUAN ELECTRONIC PROD SUPERVISION & INSPECTION INST
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511237711.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-01
Publication Date
2025-12-12
Estimated Expiration
2045-09-01

AI Technical Summary

Technical Problem

Existing technologies cannot securely and reliably grant temporary driving permissions in areas without network coverage, especially in emergency situations where it is impossible to authenticate and authorize passengers or rescue personnel.

Method used

A security authentication method based on the collaboration between BeiDou short message service and vehicle display terminal collects biometric information through the vehicle display terminal, generates a temporary driving permission application package, and sends it to the back-end authentication center for multi-dimensional verification through the vehicle-mounted BeiDou terminal. A temporary driving token is then generated and issued. The vehicle-mounted security chip and the display terminal work together to verify the legality of the token to activate the permission.

Benefits of technology

In an environment without network access, safe driving permissions are granted in emergency scenarios, ensuring the secure transmission of identity and status information, establishing a remote centralized decision-making mechanism, and improving the security of permission activation through localized verification, forming a complete request-authentication-authorization-activation closed loop.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120750550B_ABST
    Figure CN120750550B_ABST
Patent Text Reader

Abstract

The application provides a safety authentication method based on Beidou short message and vehicle display terminal cooperation, and relates to the technical field of safety authentication, and the method comprises the following steps: in response to an in-vehicle emergency event trigger signal, collecting biological characteristic information of a temporary driver; processing the biological characteristic information to generate a biological characteristic hash value and constructing a temporary driving permission application package; sending the temporary driving permission application package to a background authentication center in the form of a Beidou short message; performing multidimensional inspection on the temporary driving permission application package, and generating a temporary driving token and issuing it to the corresponding vehicle through a Beidou short message after the inspection is passed; and the vehicle-mounted safety chip and the display terminal cooperate to verify the legality of the token, activate the temporary driving permission after the verification is passed, and start safety driving monitoring. The application utilizes the Beidou short message communication capability, combines the cooperation of the vehicle display terminal and the vehicle-mounted safety chip, and can realize safe emergency temporary driving permission granting when the vehicle loses public mobile network connection.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of security authentication, and particularly relates to a security authentication method based on Beidou short message and cooperation of a vehicle display terminal. BACKGROUND

[0002] With the continuous improvement of the intelligence level of vehicles, higher requirements are put forward for the accurate management of driving permissions of shared vehicles, rental vehicles and the like. The existing technology usually relies on network connection for driver identity verification and authorization.

[0003] However, when the vehicle is in a network coverage-free area (such as a remote area or encounters network failure), and the original authorized driver cannot continue to drive due to a sudden health event (for example, a disease or injury affecting driving safety), the existing technology cannot realize the safe and reliable temporary driving permission granting for the same-ride personnel or rescue personnel.

[0004] Therefore, there is an urgent need for an emergency authorization method for temporary driving permission that can be safe, efficient and verifiable in a public network-free environment, so as to meet the safety transfer needs of vehicles in emergency situations. SUMMARY

[0005] In order to solve the technical problems in the related art, the present application provides a security authentication method based on Beidou short message and cooperation of a vehicle display terminal.

[0006] In order to achieve the above-mentioned purpose, the technical scheme adopted by the present application is as follows:

[0007] The security authentication method based on Beidou short message and cooperation of a vehicle display terminal comprises the following steps:

[0008] Step S1: In response to an in-vehicle emergency event trigger signal, biological feature information of a temporary driver is collected through a vehicle display terminal;

[0009] Step S2: The biological feature information is processed to generate a biological feature hash value, and a temporary driving permission application package containing a vehicle Beidou communication key, a displacement identification code, a Beidou time stamp, a Beidou positioning Geohash code and the biological feature hash value is constructed;

[0010] Step S3: The temporary driving permission application package is sent to the background authentication center in the form of a Beidou short message through a vehicle-mounted Beidou terminal;

[0011] Step S4: The background authentication center performs multi-dimensional verification on the temporary driving permission application package, and generates a temporary driving token and issues it to the corresponding vehicle through a Beidou short message after the verification is passed;

[0012] Step S5: The vehicle-mounted security chip and the display terminal cooperate to verify the legality of the token, activate the temporary driving permission after verification, and start the safety driving monitoring.

[0013] Optionally, in the step S1, the in-vehicle emergency event trigger signal satisfies:

[0014] Triggered by the original authorized driver through the biological feature verification on the car display terminal; or,

[0015] Triggered by the vehicle-mounted vital sign monitoring system when detecting sudden illness or injury of the driver.

[0016] Optionally, in the step S2, the step of generating the biological feature hash value includes:

[0017] Step S2-1: Concatenate the original biological feature data , the vehicle unique hardware key , and the Beidou time stamp .

[0018] Step S2-2: Calculate by hash algorithm:

[0019]

[0020] In the formula, represents the generated biological feature hash value, represents the data concatenation operation, and SHA-256 represents the secure hash algorithm.

[0021] Optionally, in the step S2, the data length of the temporary driving permission application package is between 475 bytes and 485 bytes, and the temporary driving permission application package takes the vehicle Beidou communication key as the encryption header.

[0022] Optionally, in the steps S3 and S4, the transmission of the Beidou short message adopts single transmission of the Beidou No. 3 third-class communication card.

[0023] Optionally, in the step S4, the multi-dimensional verification includes key timeliness verification, and the verification condition is:

[0024]

[0025] In the formula, is the Beidou time stamp in the temporary driving permission application package received by the background authentication center, is the local time stamp of the background authentication center, is the maximum allowed time difference threshold.

[0026] Optionally, the multi-dimensional verification also includes position rationality verification:

[0027] Calculate the positional deviation using the Haversine formula:

[0028]

[0029] In the formula, D represents the spherical distance between the two locations, and R is the Earth's radius. Due to latitude difference, This is the latitude value of the vehicle's last valid location. The latitude value of the BeiDou positioning location in the current temporary driving permission application package. Difference in longitude;

[0030] The verification conditions are:

[0031]

[0032] In the formula, The maximum reasonable displacement speed of the vehicle. This refers to the BeiDou time synchronization timestamp in the temporary driving permission application package received by the backend authentication center. This is the timestamp corresponding to the vehicle's last valid location.

[0033] Optionally, the multi-dimensional verification also includes biometric matching verification:

[0034] Retrieve records from the anonymized database that meet the Hamming distance threshold:

[0035]

[0036] In the formula, Let Hamming distance function be used. This represents the generated biometric hash value. For the pre-stored legitimate biometric hash values ​​in the de-identified database, This is the Hamming distance fault tolerance threshold.

[0037] Optionally, the generation and verification of the temporary driving token includes:

[0038] Token structure:

[0039] In the formula, Token represents the digital signature data structure of the temporary driving token. This indicates an ECDSA elliptic curve digital signature. This indicates a data concatenation operation. This represents the generated biometric hash value. This indicates the expiration timestamp of the temporary driving token; Nonce represents a random number.

[0040] Vehicle security chip verification:

[0041]

[0042] in, To verify the signature using the vehicle's public key, This represents Boolean logic, where both conditions must be satisfied simultaneously. Indicates the current time of the vehicle's onboard system. This indicates the expiration timestamp of the temporary driving token.

[0043] Optionally, in step S5, the safe driving monitoring includes:

[0044] Speed ​​limit control is triggered when the real-time vehicle speed exceeds the set threshold.

[0045] The destination for temporary driving permission is limited to the set of coordinates of the nearest hospital or rescue station;

[0046] If the vehicle's real-time location exceeds the electronic fence corresponding to the navigation route of the coordinate set, a secondary response to the emergency event inside the vehicle is triggered.

[0047] Beneficial effects:

[0048] 1. In this embodiment, the present invention utilizes the BeiDou short message communication capability and combines the collaboration between the vehicle display terminal and the vehicle-mounted security chip to realize an emergency temporary driving permission security granting mechanism in which a remote back-end authentication center makes centralized security decisions and local devices collaboratively perform verification when the vehicle loses its public mobile network connection.

[0049] Specifically, firstly, the method of this invention can overcome network limitations and enable permission requests to be initiated in emergency scenarios. The core of this method lies in utilizing BeiDou short message service for communication, which allows the system to proactively initiate permission requests even when the vehicle is in a cellular network blind spot. Specifically, step S1 responds to an emergency event by collecting biometric data through the vehicle's display terminal; step S2 constructs an application packet; and step S3 explicitly specifies that the application packet is sent via the vehicle's BeiDou terminal in the form of BeiDou short messages. This constitutes a complete request initiation chain that does not rely on public mobile networks.

[0050] Second, the method of this invention enables secure transmission of remote identity and status. The method integrates the temporary driver's biometric information with the vehicle's key status information and security credentials into a structured temporary driving permission application package. This package, containing identity and status information, is then securely and reliably transmitted to a remote backend authentication center via BeiDou short message service. Specifically, step S2 constructs an application package containing a biometric hash value, the vehicle's BeiDou communication key, a displacement identifier code, a BeiDou time stamp, and a BeiDou positioning Geohash code; step S3 sends this package via BeiDou short message service. This ensures that the backend authentication center receives the crucial identity and location / time information used for decision-making even without a network connection.

[0051] Third, the method of this invention can establish a centralized security decision-making mechanism for a remote backend. The method of this invention designs a backend authentication center that performs multi-dimensional verification on received application packets. After the verification is passed, the backend authentication center generates and issues a temporary driving token. This ensures that even in a network-free environment, the decision-making power for granting permissions remains centralized in a professional backend system with stronger security capabilities, rather than relying entirely on an unreliable local environment.

[0052] Fourth, the method of this invention enables localized security token verification and permission activation. The method requires the in-vehicle security chip and the display terminal to collaborate in verifying the legitimacy of the temporary driving token issued from the backend. Only after successful verification is the temporary driving permission activated, ensuring that the final activation of the permission depends on the joint confirmation of the security chip and the display terminal, thereby effectively improving the security of local verification.

[0053] Fifth, the method of this invention can form a complete "request-authentication-authorization-activation" security closed loop. Specifically, step S1 corresponds to local triggering and biometric data collection, step S2 corresponds to local information integration and security processing, step S3 corresponds to offline communication transmission, step S4 corresponds to remote centralized authentication and authorization decision-making, and step S5 corresponds to local security verification and permission execution. Thus, the method of this invention utilizes BeiDou short message service as a communication bridge, a background authentication center as a trust anchor, and the vehicle display terminal and security chip as local execution units to construct a self-consistent, end-to-end emergency driving permission security authentication and granting closed-loop system under conditions without a public network.

[0054] 2. Other beneficial effects or advantages of the present invention will be described in detail in the specific embodiments. Attached Figure Description

[0055] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0056] in,

[0057] Figure 1 This is a flowchart illustrating the steps of a security authentication method based on the collaboration between BeiDou short message service and automotive display terminal, provided by an exemplary embodiment of the present invention. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are some embodiments of the present invention, but not all embodiments.

[0059] To facilitate a clearer and more accurate understanding of the technical solutions of this invention by those skilled in the art, the following will take a specific application scenario as an example to provide a more detailed explanation of the existing related technologies and their technical problems.

[0060] I. Scenario Description

[0061] Location: A scenic but rarely visited mountain road at the border of Xinjiang Uygur Autonomous Region and Tibet Autonomous Region;

[0062] Vehicle: A smart connected SUV rented from a car-sharing platform (relies on cellular network authorization);

[0063] Personnel: Original authorized driver A (renter, holding a valid driver's license, who has completed biometric identification and authorization through the platform APP), passenger B (not renter, holding a valid driver's license, but not authorized to drive the vehicle in this rental);

[0064] Incident: After driving for several hours, A suddenly fell ill and was unable to continue driving the vehicle safely. The vehicle was brought to an emergency stop in a safe area on the side of the road.

[0065] II. Urgent Needs

[0066] Passenger B needs to immediately gain driving privileges to take passenger A to the nearest county hospital (approximately 80 kilometers away) for treatment. The vehicle must have all driving restrictions lifted for passenger B (e.g., starting the vehicle, releasing the electronic parking brake, etc.).

[0067] III. Deficiencies of Existing Technology

[0068] First, because the road section is located in a remote area with no network signal coverage, the vehicle cannot connect to the cloud server of the car-sharing platform via the network, and therefore cannot be authorized based on the network signal (for example, through secondary authorization via the APP, SMS verification code, or remote unlocking).

[0069] Second, if A suffers from a sudden illness (e.g., severe altitude sickness, vertigo, etc.), he may be in a semi-comatose or comatose state and may not be able to perform effective biometric identification or local offline operation to actively authorize B.

[0070] In view of this, how to implement a secure, efficient, and verifiable method for granting temporary driving permissions in the absence of a public network environment, so as to meet the needs of safe vehicle transfer in emergency situations, has become an urgent problem to be solved.

[0071] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings.

[0072] like Figure 1 As shown, this invention provides a security authentication method based on the collaboration between BeiDou short message service and automotive display terminals, comprising the following steps:

[0073] Step S1: In response to an emergency event trigger signal inside the vehicle, collect the biometric information of the temporary driver through the vehicle display terminal;

[0074] Step S2: Process the biometric information to generate a biometric hash value, and construct a temporary driving permission application package containing the vehicle's BeiDou communication key, displacement identifier code, BeiDou time synchronization timestamp, BeiDou positioning Geohash code, and biometric hash value;

[0075] Step S3: Send the temporary driving permission application package to the background authentication center via Beidou short message through the vehicle-mounted Beidou terminal;

[0076] Step S4: The background authentication center conducts multi-dimensional verification of the temporary driving permission application package. After the verification is passed, a temporary driving token is generated and sent to the corresponding vehicle via Beidou short message.

[0077] Step S5: The vehicle-mounted security chip and the display terminal work together to verify the validity of the token. After successful verification, temporary driving privileges are activated and safe driving monitoring is initiated.

[0078] In this embodiment, the present invention utilizes the BeiDou short message communication capability and combines the collaboration between the vehicle display terminal (biometric data collection) and the vehicle-mounted security chip (token verification) to realize an emergency temporary driving permission security granting mechanism in which a remote back-end authentication center makes centralized security decisions and local devices collaboratively perform verification when the vehicle loses its public mobile network connection.

[0079] Specifically, firstly, the method of this invention can overcome network limitations and enable permission requests to be initiated in emergency scenarios. The core of this method lies in utilizing BeiDou short message service for communication (step S3), which allows the system to proactively initiate permission requests even when the vehicle is in a cellular network blind spot (e.g., remote mountainous areas, deserts, disaster areas). Specifically, step S1 responds to an emergency event by collecting biometric data through the vehicle's display terminal; step S2 constructs an application packet; and step S3 explicitly indicates that the application packet is sent via the vehicle's BeiDou terminal in the form of BeiDou short messages. This constitutes a complete request initiation chain that does not rely on public mobile networks.

[0080] Second, the method of this invention enables secure transmission of remote identity and status. The method integrates the temporary driver's biometric information (processed into a hash value) with the vehicle's key status information (displacement identifier, BeiDou positioning Geohash code, BeiDou time synchronization timestamp) and security credentials (vehicle BeiDou communication key) into a structured temporary driving permission application package (step S2). This package, containing identity and status information, is then securely and reliably transmitted to a remote backend authentication center via BeiDou short message service (step S3). Specifically, step S2 constructs an application package containing the biometric hash value, vehicle BeiDou communication key, displacement identifier, BeiDou time synchronization timestamp, and BeiDou positioning Geohash code; step S3 sends this package via BeiDou short message service. This ensures that the backend authentication center receives the crucial identity and location / time information for decision-making even without network connectivity.

[0081] Third, the method of this invention can establish a centralized security decision-making mechanism for a remote backend. The method of this invention designs a backend authentication center to perform multi-dimensional verification on the received application packet (step S4). After the verification is passed, the backend authentication center generates and issues a temporary driving token. This ensures that even in a network-free environment, the decision-making power for granting permissions remains centralized in a professional backend system with stronger security capabilities, rather than relying entirely on an unreliable local environment.

[0082] Fourth, the method of this invention enables localized security token verification and permission activation. The method requires the in-vehicle security chip and the display terminal to collaborate in verifying the legitimacy of the temporary driving token issued from the backend (step S5). Only after successful verification is the temporary driving permission activated. This ensures that the final activation of the permission depends on the joint confirmation of the security chip (which typically has higher tamper-proof capabilities) and the display terminal (human-machine interface), thereby effectively improving the security of local verification.

[0083] Fifth, the method of this invention can form a complete "request-authentication-authorization-activation" security closed loop. Specifically, step S1 corresponds to local triggering and biometric data collection (input), step S2 corresponds to local information integration and secure processing (encapsulation), step S3 corresponds to offline communication transmission (channel), step S4 corresponds to remote centralized authentication and authorization decision-making (core), and step S5 corresponds to local security verification and permission execution (output). Thus, the method of this invention utilizes BeiDou short message service as a communication bridge, a background authentication center as a trust anchor, and the vehicle display terminal and security chip as local execution units to construct a self-consistent, end-to-end emergency driving permission security authentication and granting closed-loop system under conditions without a public network.

[0084] In one embodiment of the present invention, in step S1, the in-vehicle emergency event trigger signal satisfies the following conditions: it is actively triggered by the original authorized driver after completing biometric verification through the vehicle display terminal; or it is automatically triggered by the in-vehicle vital signs monitoring system when it detects that the driver has a sudden illness or injury.

[0085] In this embodiment, the method of the present invention sets strict, reliable triggering conditions for the initiation of the entire security authentication process, covering different emergency scenarios. This ensures that the system is activated only when truly necessary and controllable, significantly improving the system's security and reliability. Specifically, firstly, this embodiment ensures the proactive controllability of the process initiation (for scenarios where the driver is conscious). The first triggering condition requires the original authorized driver to actively trigger the process after completing biometric verification via the vehicle's display terminal. This ensures that when the original driver is conscious and possesses certain operational capabilities, but decides to temporarily transfer driving rights to another person due to unforeseen circumstances (e.g., leg or hand ailment, or injury but still conscious), the system can be activated. Simultaneously, this condition uses strong identity authentication (biometric verification, such as fingerprint or facial recognition) to ensure that the triggering request originates from the legitimate original driver, preventing malicious or accidental triggering of the process by others.

[0086] Secondly, this implementation method ensures the passive emergency response capability of the process initiation (for scenarios where the driver is incapacitated). Specifically, the second triggering condition allows the onboard vital signs monitoring system to automatically detect and initiate the emergency authorization process when the driver experiences a sudden illness or injury. This addresses the issue of the original driver suffering a severe condition (such as heart disease or severe trauma) resulting in complete loss of consciousness or operational ability, making it unable to actively request assistance. The system can automatically detect and initiate the emergency authorization process. Simultaneously, this condition significantly enhances the system's emergency response capability in the most critical situations (driver incapacity). It does not rely on the driver's active operation but automatically judges and triggers the process through objective physiological indicator monitoring, ensuring that even when the driver is unable to save themselves, the system can still promptly initiate the rescue process, buying valuable rescue time for the occupants of the vehicle.

[0087] Third, whether triggered proactively by the original driver's biometric verification or automatically by the vehicle system based on objective detection of vital signs, both methods provide strong initial legitimacy for subsequent permission requests. This implementation ensures that the activation signal either originates from an explicit authorization action by a legitimate user (combined with biometric verification) or from a reliable detection of objective life-threatening situations. This fundamentally reduces the risk of system abuse or accidental activation, enhances the trust foundation of the backend authentication center when reviewing received application packages, and strengthens the legitimacy of ultimately granting temporary permissions.

[0088] In one embodiment of the present invention, step S2 of the present invention, the step of generating biometric hash values ​​may include: step S2-1: converting the original biometric data... Vehicle unique hardware key and BeiDou time stamp Perform concatenation; Step S2-2: Calculate using a hash algorithm: In the formula, This represents the generated biometric hash value. This indicates a data concatenation operation, and SHA-256 represents a secure hash algorithm.

[0089] In this embodiment, the method of the present invention can significantly improve the security, uniqueness and anti-attack capability of biometric information processing, providing a more reliable and tamper-proof identity credential foundation for subsequent remote authentication and local token verification.

[0090] Specifically, firstly, it can prevent the risk of leakage of raw biometric data. This implementation does not directly transmit or store raw biometric data (such as fingerprint data, facial data), but generates its hash value. Even if the application packet is intercepted or leaked during transmission or background storage, it is extremely difficult for attackers to deduce the raw biometric features from the hash value, effectively protecting users' sensitive biometric privacy.

[0091] Secondly, it enhances the uniqueness and binding nature of biometric data. The hash value generated by this implementation method depends not only on the original biometric data. It is also bound to a unique hardware key for a specific vehicle. and the current BeiDou time stamp This allows the same person to be in different vehicles. Different) or the same vehicle at different times ( (Different), even if the same original biological characteristics are collected. Calculated It is also completely different, so that the This temporary authorization request is specific to a specific vehicle at a specific time.

[0092] Third, it can effectively resist replay attacks. Even if an attacker intercepts a valid temporary driving permission request packet (containing a certain...) Furthermore, it's not easy to simply replay the package to regain authorization. This is because... The generation includes the BeiDou time stamp. When the backend authentication center conducts multi-dimensional verification, it will inevitably check the reasonableness of the timestamp (such as its timeliness). An expired timestamp... corresponding It will become invalid, and at the same time, because It is part of the input, replaying the old packet. It also cannot be used for new requests (the timestamp has changed).

[0093] Fourth, it can prevent forgery across vehicles / requests. An attacker cannot forge a valid request obtained from vehicle A. (corresponding to specific) and ) used to forge an application for vehicle B, or to submit a single request Used for another request. Its working principle also stems from the binding of input data. Unique hardware key for the vehicle and specific timestamps Strong binding. Vehicle B has different... The application package received by the back-end certification center Must be generated Used at time Consistent and valid, different request timestamps They are different.

[0094] Fifth, it lays the foundation for secure and efficient remote matching. It transmits and stores fixed-length (256 bits for SHA-256 output) hash values. Instead of raw biological data of variable length, this significantly reduces the amount of data that needs to be transmitted (especially valuable BeiDou short message resources) and stored, improving efficiency. At the same time, the hash value format provides a convenient and secure basis for rapid comparison and verification in the background.

[0095] In this implementation, it should be noted that, firstly, for data splicing ( In terms of ), the principle is to combine three key data elements ( Raw biometric data, such as fingerprints and facial features; The vehicle's unique key, usually stored in the vehicle's security chip, is difficult to extract and is used to uniquely identify the vehicle; The BeiDou time stamp (a high-precision, reliable time source provided by the BeiDou satellite system) is sequentially linked into a single data block to strongly bind biometric features to a specific vehicle and a specific time. Any change to any element will result in a significant change in the final hash value.

[0096] Second, for the cryptographically secure hash function (SHA-256), it receives input data (i.e., the concatenated data). After complex mathematical operations (multiple rounds of compression and transformation), a fixed-length (256 bits, 32 bytes) binary string, i.e., the hash value, is output. This ensures determinism (the same input always produces the same output), efficiency (hash value calculation is relatively fast), and one-wayness (resistant to mirror attacks; specifically, for a given hash value...). It is computationally infeasible to find any method that can generate this. The original input is protected to safeguard biometric privacy; the avalanche effect (a small change in the input data, such as changing only one bit, can cause a huge and unpredictable change in the output hash value); and collision resistance (it is computationally infeasible to find two different input data that would produce the same hash). This ensures that the uniqueness of the hash value represents the uniqueness of its corresponding input.

[0097] In one embodiment of the present invention, in step S2, the data length of the temporary driving permission application packet is between 475 bytes and 485 bytes, and the temporary driving permission application packet uses the vehicle Beidou communication key as the encryption header.

[0098] Thus, in this embodiment, the method of the present invention can optimize the transmission efficiency of BeiDou short messages and enhance data confidentiality, ensuring that critical information is delivered securely and reliably to the back-end authentication center in a restricted channel.

[0099] Specifically, firstly, this implementation method ensures the feasibility of a single transmission of BeiDou short messages. This method strictly limits the data length of the application packet to between 475 and 485 bytes, ensuring that the data packet can adapt to the payload capacity limitations of the BeiDou short message communication system (especially the BeiDou-3 system) for a single message transmission. This avoids transmission failure due to excessively large data packets or the need for complex fragmentation / reassembly mechanisms, maximizing the guarantee that "the temporary driving permission application packet is sent in the form of a BeiDou short message via the vehicle-mounted BeiDou terminal" can be successfully sent in one complete transmission.

[0100] Secondly, it can improve communication efficiency and reliability. In this implementation, the fixed and compact length range (475-485 bytes) not only helps to reduce transmission time (shorter messages take less time to transmit in satellite channels), but also reduces the impact of bit error rate (in poor channel conditions, shorter messages are less likely to have uncorrectable bit errors than long messages, increasing the probability of successful reception on the first try). In addition, it can simplify protocol processing (the backend authentication center does not need to handle message fragmentation or complex length adaptation logic, making processing more efficient).

[0101] Third, it enhances the confidentiality of data transmission. In this implementation, the application packet uses the vehicle's BeiDou communication key as the encryption header. This means that the entire application packet (or its core part) is encrypted using this key, or that the key serves as an index for decryption / verification. This ensures that even if the application packet is intercepted when transmitted through the public BeiDou short message channel, attackers cannot easily read its sensitive content (such as displacement identification codes, BeiDou positioning Geohash codes, biometric hash values, etc.).

[0102] The encryption header serves two purposes: identifying the key (the encryption header itself may contain a key identifier or processed information that tells the receiver which key to use to decrypt the subsequent payload) and encapsulating encrypted data (the entire data packet or the part excluding the header is ciphertext encrypted using that key; the encryption header may contain an initialization vector, algorithm identifier, or integrity verification information).

[0103] Fourth, using the vehicle's BeiDou communication key as the encryption header enables the backend authentication center to quickly locate or identify the correct key used to decrypt the application packet after receiving the message, thus improving decryption efficiency.

[0104] In this embodiment, it should be noted that, firstly, regarding the data packet length limit, since the short message service of the Beidou satellite system has clear regulations and strict restrictions on the length of the user data area of a single message, when designing the application packet structure, it is necessary to accurately calculate the typical or maximum lengths of each field (vehicle Beidou communication key, displacement identification code, Beidou time synchronization timestamp, Beidou positioning Geohash code, biometric hash value), and optimize them (such as selecting a compact Geohash precision, fixed-length hash algorithm output like SHA-256 = 32 bytes) to ensure that the total strictly falls within the range of 475 - 485 bytes.

[0105] Secondly, regarding the encryption header, this is a data encapsulation and key management strategy. It can have multiple specific implementation methods. For example, in one implementation method, it serves as a key identifier / index, that is, the encryption header part contains an identifier representing or pointing to the vehicle Beidou communication key, and the background can quickly retrieve the corresponding key based on this identifier to decrypt the rest of the data packet (ciphertext). Another example is that in another implementation method, the encryption header can contain an initialization vector encrypted or derived using this key, a fragment of the message authentication code, or other encryption and decryption-related parameters. The entire data packet (or the part after the encryption header) is ciphertext encrypted using this key, and the receiving party has a pre-shared key and can quickly decrypt it by combining the information in the header. Generally speaking, regardless of which implementation method is adopted in the specific implementation, its core principle is to place the key information (or information index) required for decryption at the beginning of the data packet for the receiving party to quickly locate and process, and at the same time clearly indicate the key identity used to protect the subsequent data. Using the vehicle Beidou communication key ensures the encryption strength (pre-shared secret) and the verifiability of the vehicle identity (only legal vehicles have this key).

[0106] In an embodiment of the present invention, in steps S3 and S4 of the present invention, the Beidou short message is transmitted using a single transmission of a Beidou-3 level-3 communication card. In this way, on the premise of ensuring the basic communication ability, by selecting a specific level of Beidou civil service, it is possible to achieve cost control, resource predictability, and transmission determinacy in the communication link of the emergency authorization process.

[0107] Specifically, firstly, level-3 communication cards are usually easier to obtain, have lower costs, and simpler user qualification reviews. This makes this technical solution economically feasible and has the potential for large-scale promotion in actual deployment (such as shared car fleets).

[0108] Secondly, the transmission of BeiDou short messages is completed within a single transmission. This means that whether sending a temporary driving permission request packet or issuing a temporary driving token, it is designed to be completed within a single BeiDou short message, without the need for fragmentation or reassembly. This effectively avoids complex multi-packet transmission protocols, simplifies sending and receiving logic, reduces transmission latency, and significantly improves the probability and speed of successful communication in emergency situations.

[0109] In one embodiment of the present invention, in step S4, the multi-dimensional verification includes key validity verification, the verification conditions of which are: In the formula, This refers to the BeiDou time synchronization timestamp in the temporary driving permission application package received by the backend authentication center. For the local timestamp of the backend authentication center, This is the maximum allowable time difference threshold.

[0110] In this implementation, the high-precision and reliable time reference provided by BeiDou time synchronization is used to establish a strict and reliable time trust anchor point for the entire security authentication process, effectively resisting security threats based on time differences and ensuring the real-time nature and freshness of authorization requests.

[0111] Specifically, firstly, it can resist replay attacks. Even if an attacker intercepts a valid temporary driving permission request packet (containing its valid timestamp at that time), it will still be able to resist replay attacks. Furthermore, it's impossible to simply replay the old package at a later time (e.g., minutes, hours, or even days later) to trick the backend into granting authorization. This is because the backend authentication center extracts information from the package upon receiving it. (i.e., the old timestamp replayed by the attacker), and compared with the local timestamp in the background. (Representing the current real time) are compared. Based on the verification conditions. If the time difference exceeds the maximum allowed threshold Verification will fail. An expired old package ( much smaller This will inevitably fail the verification.

[0112] Second, it can prevent delay attacks. It prevents attackers from maliciously delaying the transmission of legitimate request packets (e.g., by interfering with satellite signals or intermediate nodes), causing the backend to receive the packet long after the request has actually occurred. Even if the attacker does not actively forge packets, but merely obstructs the timely transmission of legitimate packets, thus delaying the backend's receipt of the packet... Much larger than the number recorded in the package (BeiDou time stamp), then The value will also be large. As long as this difference exceeds... If the request times out, the backend will determine that it is invalid and refuse authorization. This ensures that the backend only processes fresh requests that arrive within a reasonable time window.

[0113] In this embodiment, it should be noted that the maximum allowable time difference threshold... Specifically, its value can be determined through engineering trade-offs based on the actual network environment, system processing capacity, and security requirements. The lower limit can be considered to be greater than the sum of the BeiDou signal propagation delay, satellite relay delay, ground station processing delay, network transmission delay, and background processing queue waiting time, to ensure that legitimate, interference-free requests have a sufficient time window to reach the background. The upper limit can be considered sufficiently small to effectively limit the window period for replay attacks.

[0114] In one embodiment of the present invention, the multi-dimensional verification may further include location rationality verification: calculating the location deviation using the Haversine formula.

[0115]

[0116] In the formula, D represents the spherical distance between the two locations, and R is the Earth's radius. Due to latitude difference, This is the latitude value of the vehicle's last valid location. The latitude value of the BeiDou positioning location in the current temporary driving permission application package. Difference in longitude;

[0117] The verification conditions are: In the formula, The maximum reasonable displacement speed of the vehicle. This refers to the BeiDou time synchronization timestamp in the temporary driving permission application package received by the backend authentication center. This is the timestamp corresponding to the vehicle's last valid location.

[0118] In this embodiment, the method of the present invention utilizes highly reliable location information provided by BeiDou, combined with accurate spherical distance calculation and vehicle kinematic constraints, to effectively identify and prevent attacks based on forged locations, ensuring that the geographical location of temporary driving permission requests is authentic and reliable.

[0119] Specifically, firstly, it can resist location spoofing attacks. Attackers cannot forge seemingly plausible vehicle location information (BeiDou positioning Geohash encoding) in an application packet sent to the backend from a location far from the vehicle's actual location (e.g., in an attacker's lab) to trick the backend into granting authorization. This is because the backend compares the current location in the application packet with the vehicle's last valid location and its corresponding timestamp stored in the database. It calculates the spherical distance D between the two locations using the Haversine formula, and simultaneously calculates the time difference between the two locations. Verification conditions The distance the vehicle travels within the time difference must not exceed the vehicle's maximum reasonable displacement speed. The achievable distance. For example, if an attacker fabricates a very distant location, the calculated distance D will be very large, and the time difference... It is finite. It's a physical limit; falsifying location almost inevitably leads to... This leads to the verification failure.

[0120] Second, it can detect abnormal displacement (abnormal driving behavior or trailer hijacking). Even if it is not a malicious attack, if the vehicle undergoes abnormal displacement that exceeds physical limits (for example, the vehicle is loaded onto a truck and quickly transported away, or the positioning system malfunctions and drifts), the verification method can identify it as a suspicious situation and reject the authorization request.

[0121] In one embodiment of the present invention, the multi-dimensional verification may further include biometric matching verification: retrieving records that meet the Hamming distance threshold from a de-identified database. In the formula, Let Hamming distance function be used. This represents the generated biometric hash value. For the pre-stored legitimate biometric hash values ​​in the de-identified database, This is the Hamming distance fault tolerance threshold.

[0122] Thus, in this embodiment, the method of the present invention can achieve efficient, reliable and fault-tolerant identity authentication by comparing biometric hash values ​​using Hamming distance, while protecting user biometric privacy, thereby ensuring the legitimacy of the identity of the temporary driving permission requester.

[0123] Specifically, firstly, it enables privacy-preserving biometric authentication. This is because the verification process does not involve raw biometric data (such as fingerprint images or facial photos). The backend operation only processes the biometric hash value. and the pre-stored hash value in the de-identified database Even if the backend database is compromised, attackers can only obtain irreversible hash values ​​and cannot reconstruct the original biometric features, thus effectively protecting users' biometric privacy and security.

[0124] Secondly, it provides efficient binary comparison capabilities. Hamming distance (HD) is a metric for calculating the number of bits (bit flips) that differ between two binary strings of equal length. Its computation is extremely efficient, making it particularly suitable for urgent scenarios requiring rapid response to requests in the background.

[0125] Third, it possesses the necessary fault tolerance capability. This implementation sets a Hamming distance fault tolerance threshold. As long as the difference in bits between two hash values Not greater than If a match is found, it is considered successful. This allows for some differences in data collection (biometric data collected from the same person at different times, in different postures, or using different sensors, which are then hashed to generate a match). There may be slight bit differences), and it can be adapted to application scenarios with some environmental noise (vibration during vehicle operation, changes in lighting, etc., may introduce minor noise). Specifically, regarding the Hamming distance fault tolerance threshold... In this regard, its settings need to strike a balance between security (preventing impersonation) and usability (reducing the rejection of legitimate users).

[0126] In one embodiment of the present invention, the generation and verification of the temporary driving token may include:

[0127] Token structure: In the formula, Token represents the digital signature data structure of the temporary driving token. This indicates an ECDSA elliptic curve digital signature. This indicates a data concatenation operation. This represents the generated biometric hash value. This indicates the expiration timestamp of the temporary driving token; Nonce represents a random number.

[0128] Vehicle security chip verification: ;in, To verify the signature using the vehicle's public key, This represents Boolean logic, where both conditions must be satisfied simultaneously. Indicates the current time of the vehicle's onboard system. This indicates the expiration timestamp of the temporary driving token.

[0129] In this embodiment, the method of the present invention uses asymmetric cryptography (ECDSA) to create a tamper-proof, verifiable and time-sensitive digital authorization credential for temporary driving permissions, and achieves efficient local verification through an on-board security chip to ensure the security and autonomy of permission activation.

[0130] Specifically, firstly, it can create tamper-proof digital authorization credentials (tokens). A token is essentially a backend authentication center's authentication of specific information (…). , Digital signatures of Nonce Based on the cryptographic properties of the Elliptic Curve Digital Signature Algorithm (ECDSA), any tampering with the token content (whether it is the signature payload or the signature itself) will be detected, leading to verification failure.

[0131] Second, it enables trusted authorization from the backend authentication center. Only entities holding the private key of the backend authentication center can generate valid authorization. The signature ensures that the token originates from a legitimate backend authentication center and serves as unforgeable proof of the backend authorization decision.

[0132] Third, regarding the signature payload of the token ( , Regarding Nonce, among them Used to identify authorized temporary drivers, Define an expiration timestamp for the token to ensure that the permission is temporary. The Nonce is a random number to ensure that each generated token is unique and to prevent token reuse.

[0133] Fourth, token verification is entirely performed on the vehicle's in-vehicle side, completed collaboratively by the vehicle's security chip and the display terminal. The verification process only requires: First, using the vehicle's pre-installed public key. Verify signature Second, check the current time of the vehicle's onboard system. Has the token expired yet? ECDSA signature verification is relatively efficient when the public key is known, making it particularly suitable for execution in resource-constrained in-vehicle environments. It does not require a connection to the backend, and vehicles can independently and quickly verify the legitimacy and validity of tokens even in offline environments, thus supporting efficient local offline verification.

[0134] In one embodiment of the present invention, in step S5, safe driving monitoring may include: triggering speed limit control when the real-time vehicle speed is greater than a set threshold; restricting the destination of temporary driving permission to the coordinate set of the nearest hospital or rescue station; and triggering a secondary response to an emergency event in the vehicle if the real-time location of the vehicle exceeds the electronic fence corresponding to the navigation route of the coordinate set.

[0135] In this embodiment, the method of the present invention constructs an active safety protection mechanism after the temporary driving permission is activated by real-time vehicle speed monitoring, destination restriction and electronic fence boundary detection, so as to minimize the operational risks of temporary drivers and ensure that the purpose of emergency authorization (medical transport / rescue) is not abused.

[0136] Specifically, firstly, when the system detects that the real-time vehicle speed exceeds a set threshold, it automatically triggers speed limit control (e.g., limiting motor power output, limiting throttle opening, activating electronic speed limiting function). This directly prevents temporary drivers from speeding due to nervousness, unfamiliarity with the vehicle, or road conditions, significantly reducing the risk of secondary accidents caused by excessive speed.

[0137] Second, the destination of temporary driving permission is forcibly restricted to the coordinates of the nearest hospital or rescue station. In other words, the vehicle navigation system (or underlying control system) only allows the vehicle to drive to the preset emergency rescue point coordinates and cannot arbitrarily change the destination or drive to other unrelated areas (such as shopping malls or private residences).

[0138] Third, the system will generate a dynamic electronic fence (e.g., an area within a certain width on both sides of the route) around the navigation route leading to the set of preset rescue point coordinates. If the system detects that the vehicle's real-time location has exceeded this electronic fence, it will immediately trigger a secondary response for the in-vehicle emergency, that is, restart the temporary authorization process.

[0139] Overall, speed monitoring, destination restrictions, and geofence monitoring together form a proactive, real-time safety network. When a risk (speeding, deviation) is detected, proactive intervention (speed limiting) or triggering alarms / interventions (secondary response) is implemented. This effectively enhances overall vehicle safety when driven by potentially unqualified or unfamiliar personnel after emergency authorization.

[0140] The above are merely specific embodiments of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.

Claims

1. A security authentication method based on the collaboration between BeiDou short message service and automotive display terminal, characterized in that, Includes the following steps: Step S1: In response to an emergency event trigger signal inside the vehicle, collect the biometric information of the temporary driver through the vehicle display terminal; The in-vehicle emergency event trigger signal satisfies the following: It can be triggered by the original authorized driver after completing biometric verification through the vehicle's display terminal; or by the vehicle's vital signs monitoring system automatically detecting when the driver suffers a sudden illness or injury. Step S2: Process the biometric information to generate a biometric hash value, and construct a temporary driving permission application package containing the vehicle's Beidou communication key, displacement identifier code, Beidou time synchronization timestamp, Beidou positioning Geohash code, and biometric hash value; The step of generating the biometric hash value includes: Step S2-1: Transfer the original biometric data Vehicle's unique hardware key and BeiDou time stamp To splice; Step S2-2: Calculate using a hash algorithm: In the formula, This represents the generated biometric hash value. This indicates a data concatenation operation; SHA-256 represents a secure hash algorithm. Step S3: Send the temporary driving permission application package to the background authentication center via Beidou short message through the vehicle-mounted Beidou terminal; Step S4: The background authentication center conducts multi-dimensional verification of the temporary driving permission application package. After the verification is passed, a temporary driving token is generated and sent to the corresponding vehicle via Beidou short message. The generation and verification of the temporary driving token includes: Token structure: In the formula, Token represents the digital signature data structure of the temporary driving token. This indicates an ECDSA elliptic curve digital signature. This indicates a data concatenation operation. This represents the generated biometric hash value. This indicates the expiration timestamp of the temporary driving token; Nonce represents a random number. Vehicle security chip verification: in, To verify the signature using the vehicle's public key, This represents Boolean logic, where both conditions must be satisfied simultaneously. Indicates the current time of the vehicle's onboard system. Indicates the expiration timestamp of the temporary driving token; Step S5: The vehicle security chip and the display terminal work together to verify the validity of the token. After successful verification, temporary driving privileges are activated and safe driving monitoring is started. The safe driving monitoring includes: Speed ​​limit control is triggered when the real-time vehicle speed exceeds the set threshold. The destination for temporary driving permission is limited to the set of coordinates of the nearest hospital or rescue station; If the vehicle's real-time location exceeds the electronic fence corresponding to the navigation route of the coordinate set, a secondary response to the emergency event inside the vehicle is triggered.

2. The security authentication method based on the collaboration between BeiDou short message service and automotive display terminal as described in claim 1, characterized in that, In step S2, the data length of the temporary driving permission application packet is between 475 bytes and 485 bytes, and the temporary driving permission application packet uses the vehicle Beidou communication key as the encryption header.

3. The security authentication method based on the collaboration between BeiDou short message service and automotive display terminal as described in claim 1, characterized in that, In steps S3 and S4, the transmission of the BeiDou short message uses a single transmission via a BeiDou-3 Level 3 communication card.

4. The security authentication method based on the collaboration between BeiDou short message service and vehicle display terminal as described in claim 1, characterized in that, In step S4, the multi-dimensional verification includes key timeliness verification, the verification conditions of which are: In the formula, This refers to the BeiDou time synchronization timestamp in the temporary driving permission application package received by the backend authentication center. For the local timestamp of the backend authentication center, This is the maximum allowable time difference threshold.

5. The security authentication method based on the collaboration between BeiDou short message service and vehicle display terminal as described in claim 1, characterized in that, The multi-dimensional inspection also includes location rationality verification: Calculate the positional deviation using the Haversine formula: In the formula, D represents the spherical distance between the two locations, and R is the Earth's radius. Due to latitude difference, This is the latitude value of the vehicle's last valid location. The latitude value of the BeiDou positioning location in the current temporary driving permission application package. Difference in longitude; The verification conditions are: In the formula, The maximum reasonable displacement speed of the vehicle. This refers to the BeiDou time synchronization timestamp in the temporary driving permission application package received by the backend authentication center. This is the timestamp corresponding to the vehicle's last valid location.

6. The security authentication method based on the collaboration between BeiDou short message service and automotive display terminal as described in claim 1, characterized in that, The multi-dimensional test also includes biometric matching verification: Retrieve records that meet the Hamming distance threshold from the anonymized database: In the formula, Let Hamming distance function be used. This represents the generated biometric hash value. For the pre-stored legitimate biometric hash values ​​in the de-identified database, This is the Hamming distance fault tolerance threshold.

Citation Information

Patent Citations

  • Emergency information communication system based on Beidou short message communication

    CN108322252A

  • Automobile visitor authorization system and method

    CN116403315A